captn3m0 / captn3m0/hello-cloudflare

Add Past response from cloudflare

Open
#12 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
238
Forks
12
PR merge metrics
No merged PRs in 30d

Description

I have in the past reported this issue to Cloudflare through their Hackerone page (due to the lack of appropriate platform to reach them out on), this is the response I got (if you wanna add it to the readme):

> Enabling SSL/TLS between Cloudflare and the origin site is a customer decision. When this protection is not enabled, as is the case here, an ISP can manipulate the requests before they reach Cloudflare. If this behavior is
not desired, the customer must change the settings for the site in the Cloudflare dashboard.

Full report attached:
[2022-02-10_report_1438600.pdf](https://github.com/captn3m0/hello-cloudflare/files/8039649/2022-02-10_report_1438600.pdf)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.